cbcvebase.

Microsoft Word vulnerabilities

265 known vulnerabilities affecting microsoft/word.

Total CVEs
265
CISA KEV
10
actively exploited
Public exploits
20
Exploited in wild
18
Severity breakdown
CRITICAL79HIGH142MEDIUM42LOW2

Vulnerabilities

Page 4 of 14
CVE-2014-1757P3CRITICALCVSS 9.3v2007v20102014-04-08
CVE-2014-1757 [CRITICAL] CWE-119 CVE-2014-1757: Microsoft Word 2007 SP3 and 2010 SP1 and SP2, and Office Compatibility Pack SP3, allocates memory in Microsoft Word 2007 SP3 and 2010 SP1 and SP2, and Office Compatibility Pack SP3, allocates memory incorrectly for file conversions from a binary (aka .doc) format to a newer format, which allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office File Format Converter Vulnerability."
nvd
CVE-2016-0183P3HIGHCVSS 8.8v20102016-05-11
CVE-2016-0183 [HIGH] CWE-284 CVE-2016-0183: The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on Sh The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE Vulnerability."
nvd
CVE-2018-0795P3HIGHCVSS 8.8v20132018-01-10
CVE-2018-0795 [HIGH] CVE-2018-0795: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code executio Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
nvd
CVE-2007-1910P3MEDIUMCVSS 6.8PoCv20072007-04-10
CVE-2007-1910 [MEDIUM] CVE-2007-1910: Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of ser Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
nvd
CVE-2013-3857P3CRITICALCVSS 9.3v2003v2007+1 more2013-09-11
CVE-2013-3857 [CRITICAL] CWE-119 CVE-2013-3857: Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1 and SP2, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office docu
nvd
CVE-2010-3215P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3215 [CRITICAL] CWE-94 CVE-2010-3215: Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values dur Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
nvd
CVE-2010-2750P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-2750 [CRITICAL] CWE-94 CVE-2010-2750: Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to exec Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
nvd
CVE-2010-3219P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3219 [CRITICAL] CWE-94 CVE-2010-3219: Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary co Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
nvd
CVE-2010-3221P3CRITICALCVSS 9.3v2002v20032010-10-13
CVE-2010-3221 [CRITICAL] CWE-94 CVE-2010-3221: Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
nvd
CVE-2010-3220P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-3220 [CRITICAL] CWE-94 CVE-2010-3220: Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
nvd
CVE-2017-8509P3HIGHCVSS 8.8v2007v2010+2 more2017-06-15
CVE-2017-8509 [HIGH] CVE-2017-8509: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506.
nvd
CVE-2010-2747P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-2747 [CRITICAL] CWE-94 CVE-2010-2747: Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer duri Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
nvd
CVE-2013-1335P3CRITICALCVSS 9.3v20032013-05-15
CVE-2013-1335 [CRITICAL] CWE-94 CVE-2013-1335: Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
nvd
CVE-2015-6092P3CRITICALCVSS 9.3v2007v2010+2 more2015-11-11
CVE-2015-6092 [CRITICAL] CWE-119 CVE-2015-6092: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2010-2748P3CRITICALCVSS 9.3v20022010-10-13
CVE-2010-2748 [CRITICAL] CWE-94 CVE-2010-2748: Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
nvd
CVE-2016-3282P3HIGHCVSS 7.8v2007v2010+2 more2016-07-13
CVE-2016-3282 [HIGH] CWE-119 CVE-2016-3282: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, SharePoint Server 2016, Office Web Apps 2010 SP2, Office Web
nvd
CVE-2015-1651P3CRITICALCVSS 9.3v20072015-04-14
CVE-2015-1651 [CRITICAL] CVE-2015-1651: Use-after-free vulnerability in Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack Use-after-free vulnerability in Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
nvd
CVE-2013-3848P3CRITICALCVSS 9.3v2003v2007+1 more2013-09-11
CVE-2013-3848 [CRITICAL] CVE-2013-3848: Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office We Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corrupti
nvd
CVE-2013-3858P3CRITICALCVSS 9.3v2003v2007+1 more2013-09-11
CVE-2013-3858 [CRITICAL] CVE-2013-3858: Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office We Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corrupti
nvd
CVE-2013-3849P3CRITICALCVSS 9.3v2003v2007+1 more2013-09-11
CVE-2013-3849 [CRITICAL] CVE-2013-3849: Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office We Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corrupti
nvd
Microsoft Word vulnerabilities | cvebase